logo

Russian Laundry Bear Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

ID: dbd4c4fa-2c64-5ffc-8664-1d9d9439aaa4

STIX ID: report--dbd4c4fa-2c64-5ffc-8664-1d9d9439aaa4

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-23

Date Updated: 2026-07-24

...
...

Laundry Bear (also tracked as Void Blizzard / TA488) used a zero-click stored/DOM XSS in Zimbra Collaboration (CVE-2025-66376) to silently exfiltrate 90 days of email, 2FA tokens and backup scratch codes, harvest organizational contact lists, and create persistent application passcodes; Zimbra patched the flaw on November 6, 2025 and CISA published advisory AA26-204A on July 22, 2026 with mitigation and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.